Apple Safari Fixes Cross-Origin Issue to Protect Users' Data
CVE-2024-44187
6.5MEDIUM
Key Information:
- Vendor
Apple
- Vendor
- CVE Published:
- 17 September 2024
What is CVE-2024-44187?
A vulnerability exists in Apple products due to improper handling of 'iframe' elements, which can lead to cross-origin data exfiltration. This security issue could enable malicious websites to unintentionally access sensitive user data from other domains. Apple has addressed this vulnerability in several updates, including Safari 18, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18, iPadOS 18, and tvOS 18, emphasizing the importance of keeping software up to date for personal data protection.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
iOS and iPadOS < 18
macOS < 15
Safari < 18
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published